rdmsm4x-changelog-20260826-0341-agent-control-plane-remediation
rdmsm4x agent control-plane remediation
Configured the Mac Studio's local agent, GitHub, MCP, Cursor, Grok, and worktree foundation so Claude, Codex, agy, Grok, and Cursor can operate against the same canonical Git repositories without copying credentials or native session databases.
Scope
- Changed host:
rdmsm4xonly. - Control client:
codex@rdmbair13m5over pinned-host-key SSH. - Canonical development root:
/Users/richh/dev. - No fleet-wide rollout, publication, provider-account migration, or native chat-database mutation.
Files and state changed
/Users/richh/.gitconfig/Users/richh/.codex/config.tomlthroughcodex mcp add/Users/richh/.gemini/config/mcp_config.jsonthrough supportedagy mcpcommands/Users/richh/.grok/config.toml/Users/richh/.cursor/permissions.json/Users/richh/Library/Application Support/Cursor/User/settings.json/Users/richh/.config/worktrunk/config.toml/Users/richh/.zshrcthroughwt config shell install zsh/Applications/Cursor.appand/opt/homebrew/bin/cursorthrough Homebrew/opt/homebrew/Cellar/worktrunk/0.74.0and/opt/homebrew/bin/wtthrough Homebrew/Users/richh/dev/agy/CLAUDE.md/Users/richh/dev/agy/index.html/Users/richh/dev/agy/rdDB_autoCE.MOVED.md/Users/richh/dev/SESSION-STATE.md/Users/richh/dev/PROJECTS.md/Users/richh/dev/_migration/dev-hierarchy-20260826/INGEST-MANIFEST.md- Moved clean repository from
/Users/richh/dev/agy/rdDB_autoCEto/Users/richh/dev/archive/agent-snapshots/agy/rdDB_autoCE-20260823.
Claude plugin enablement was temporarily restored to the six-plugin
historical baseline, but an active Claude remote-control writer changed
it afterward. The final observed state is two enabled plugins
(frontend-design, hookify); no second
overwrite was attempted. Coordination message:
20260826-033809-0540F067.
Commands and operations
- Inspected host/app/CLI versions, provider status exit codes, GitHub transport, configuration key names, MCP health, Tyrell service/MCP health, Git repositories, dirty state, and linked worktrees.
- Ran
gh auth setup-gitand added HTTPS rewrites for SSH-style GitHub URLs. - Set Git defaults: prune, automatic upstream, rerere, zdiff3, rebase autostash, and remote-aware worktrees.
- Added Tyrell using each supported surface:
codex mcp add,agy mcp add,grok mcp add, Claude MCP configuration, and Cursor settings. - Removed seven broad agy MCP entries using
agy mcp remove. - Installed software with
brew install --cask cursorandbrew install worktrunk. - Configured and smoke-tested Worktrunk create/list/remove against a temporary Git repository.
- Ran
git worktree prune --dry-run --verbose, backed up metadata, then pruned two confirmed missing worktree records. Compared branch refs before and after; unchanged. - Created and verified a complete Git bundle for
rdDB_autoCE, checked file SHA-256 duplicates, moved the clean repository, and verified HEAD/remote/status at the destination.
Verification evidence
git ls-remote [email protected]:richhdoty/rdmsm4x-apps-bitroo.git HEAD: exit 0 through the HTTPS credential rewrite.- Claude auth status: exit 0.
- Codex login status: exit 0.
- agy model catalog: exit 0.
- GitHub CLI auth status: exit 0.
- Grok: installed but authentication still pending.
- Grok Tyrell MCP doctor: handshake healthy, protocol
2025-11-25, five tools discovered. - agy MCP list: Tyrell only.
- Codex MCP list: Tyrell plus required bundled desktop helpers; Computer Use disabled.
- Cursor settings parse: Tyrell present; cleanup 24 hours; maximum 200 worktrees.
- Cursor policy parse: four allow and four block instructions under
autoRun. - Worktrunk:
0.74.0; smoke test printedWORKTRUNK_SMOKE=PASS. - Pruned worktree metadata:
replicantDBandscanROObranch refs unchanged. - Hierarchy archive: clean Git status, HEAD
84abcfe1c6f5, origin retained, complete bundle verified. - The two archived HTML files match their canonical copies with SHA-256 values recorded in the ingest manifest.
- Tyrell loopback API reports six fleet rows; Tyrell MCP
usage_statusreturnedholdat the final observation. No further delegation was started.
Backups
/Users/richh/dev/_ops/agent-config/backups/20260826-031743-github-git/Users/richh/dev/_ops/agent-config/backups/20260826-032025-mcp-baseline/Users/richh/dev/_ops/agent-config/backups/20260826-032123-grok-permissions.toml/Users/richh/dev/_ops/agent-config/backups/20260826-032211-cursor-baseline/Users/richh/dev/_ops/agent-config/backups/20260826-032358-claude-plugin-baseline.json/Users/richh/dev/_ops/agent-config/backups/20260826-033157-worktrunk/Users/richh/dev/_ops/agent-config/backups/20260826-033311-stale-worktree-metadata/Users/richh/dev/_ops/agent-config/backups/20260826-033437-hierarchy-rdDB_autoCE/Users/richh/dev/_ops/agent-config/backups/20260826-0345-projects-milestone/Users/richh/dev/_backups/rdDB_autoCE-all-refs-20260826-033437.bundle
Undo
- Restore only the relevant
*.beforefile from its backup directory; do not overwrite an entire config family over newer owner changes. - Remove Tyrell from a client with that client's supported MCP removal command if needed.
- Uninstall Cursor or Worktrunk with Homebrew if desired.
- For the hierarchy move, verify the archive is clean, move it back to
/Users/richh/dev/agy/rdDB_autoCE, then restore the three documentation files from the hierarchy backup and remove only the new tombstone/manifest. - The Git bundle can reconstruct all archived refs independently.
Outstanding owner actions
- Authenticate Grok in the Studio Aqua/Terminal session.
- Unlock the login Keychain and run
cursor agentonce to finish Cursor Agent CLI installation and sign-in; choose Cursor's GUI execution mode. - Optionally register the Studio public SSH key with GitHub; HTTPS Git already works.
- Connect the intended GitHub account in ChatGPT, Claude, and Cursor through each app's OAuth UI.
- Resolve the Claude plugin-writer collision before restoring or ratifying the plugin map.
- Organize native tasks/chats using supported provider project/move UIs after Tyrell indexes links; do not copy native session databases.
- Decide whether to create an OpenRouter account/key and spend guardrails; none was created here.
- Publish this changelog to Apple Notes from an Aqua session. The SSH
launchd manager is
Background, so no Notes success is claimed.